CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

2h 11mAdvanced2020-11-23

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Explore best practices and procedures for managing privacy, security, and risk and assessing security processes as you study for the CompTIA Cybersecurity Analyst (CySA+) (CS0-002) exam. In this installment of the CySA+ (CS0-002) Cert Prep series, instructor Mike Chapple provides coverage of data privacy and protection practices, risk management, and security frameworks. Mike delves into the differences between privacy and security, how to align security with the business needs of your organization, and how to assess risk likelihood and impact through qualitative and quantitative risk assessment. He also shows how to assess key security processes, including how to best leverage audits and assessments; how to mitigate risk when working with vendors; and more. After completing this course, you'll be prepared to tackle the Compliance and Assessment domain of the CySA+ (CS0-002) exam.

Skills covered

PrivacyIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Compliance and assessment
  • What you should know
  • Study resources

Privacy

  • Privacy and security
  • Limiting data collection
  • Privacy compliance
  • Privacy assessments

Security Governance

  • Aligning security with the business
  • Organizational processes
  • Security roles and responsibilities
  • Security control selection
  • Control frameworks

Nontechnical Controls

  • Information classification
  • Data security policies
  • Data security roles
  • Data sovereignty

Data Controls

  • Data anonymization
  • Data obfuscation
  • Don't use the last four digits of SSNs
  • Data loss prevention
  • Information rights management

Risk Management

  • Risk assessment
  • Quantitative risk assessment
  • Risk treatment options
  • Risk management frameworks
  • Risk visibility and reporting

Assessing Security Processes

  • Management review
  • Metrics and measurements
  • Audits and assessments
  • Control management
  • Certification and accreditation
  • Maturity models

Supply Chain Assessment

  • Managing vendor relationships
  • Vendor agreements
  • Vendor information management

Security Policies

  • Security policy framework
  • Security policies

Conclusion

  • What's next
80,000 Toman